With the use of e-mail continually increasing, the need for protection has never been more evident. All organisations and individuals with computers or networks connected to the Internet are vulnerable to malicious code and viruses. While many individuals and organisations routinely install anti-virus software and dutifully update it on a regular basis, this protection is often ineffective against the "new breed" of malicious code (viruses, worms, and Trojans) that is released into the "wild" each day. Email and the web have revolutionized business communications. Together they are the most prominent and arguably the most critical business applications in the world. It is imperative, therefore, that they be protected in a comprehensive manner. Complicating matters is the fact that high penetration and usage rates have led to email and web technologies being very attractive targets for intrusions of all types. Everything from conventional file-infecting viruses, mass-mailing worms, spam, and denial-of-service attacks to increasingly elaborate and aggressive phishing techniques and blended threats need to be addressed. Virus writers are becoming craftier every year, resulting in huge losses for organisations around the world. Phishing is up and becoming more automated. Email/Directory harvesting attacks are an everyday affair. To save an organisation from such modern day digital diseases, one must now employ a proactive, first strike approach to protect organisations all over the world and more vigilant and needful stance should be taken to shield computers and networks from digital disaster immediately. Undeniably, the greatest asset and weapon against preventing a virus attack is knowledge. Knowing apart how viruses and malicious code infiltrate computer systems, how they affect those systems, and how they ultimately spread and cause more damage exponentially is imperative and necessary. In order to engage in combating with technologically savvy virus creators in the new millennium, a new, more comprehensive approach to protect must be adopted. These new Malware writing techniques further enforce the fact that the only way to completely protect your computers on a network is through a "defense in depth" methodology. Defense in depth doesn't rely on just one method, system or application, but builds in multiple layers of protection. The use of anti-virus, anti-spyware or even a single engine anti-malware solution alone will not be able to completely prevent such outbreaks. In order to launch an effective attack against this invasion, an in-depth knowledge base is a pre-requisite. The concept and how they operate needs to be understood. Are we clear on the damage it can do? Malicious code is any program that acts in unexpected and potentially damaging ways. Common types of malicious code are viruses, worms, Trojan horses, monitoring programs such as spyware, and cross-site scripts. Malicious code can; — Replicate itself within a computer and transmit itself between computers. — Change, delete, or insert data, transmit data outside the institution, and insert backdoors into organisation systems. — Attack organisations at either the server or the client level. — Attack routers, switches, and other parts of the organisational infrastructure . Malicious code can also monitor users in many ways, such as logging keystrokes and transmitting screenshots to the attacker. The changing nature of malware attacks Malware attacks are changing from the initial days of viruses being created and let loose on the Internet. The nature of these changes is summarized in four characteristics below.
- Malware attacks are much more focused and sophisticated: Gone are the old random-style attacks. Today's malware is focused on specific organisations or users with specific behavior patterns. It largely depends on who the organisation is or what the user does, what sites are accessed online, whether material is downloaded from perilous sites, and how careful he/she is about downloading files attached to emails, and similar issues. The traditional “one solution fits all” approach to stopping attacks is no longer applicable.
- Malware changes its code constantly: The latest viruses are designed to avoid detection by AV engines by automatically changing or mutating every day and every time they send themselves out. Anti-virus vendors either have to use performance-hungry and error-prone heuristics or must create a new signature for each mutation.
- Some malware removers are actually malware: This 'greyware' represents a deceitful trap for users. Some Web sites are rumored to have deals in place with malware authors. E.g. when someone accesses the site they get a fake error message that his/her system is compromised and is urged to click a link and download a “test utility” to scan. This “test utility” is usually a piece of spyware disguised as a seemingly benign system cleaner or something similar.
- Standard antivirus programs are often ineffective: The malware designers constantly test their creations against Trend Micro, Norton, McAfee, and other popular anti-virus and anti-spyware systems, so they know those programs will not detect their malware during the zero hour when it is first released. By the time the vendors catch up, the damage is done, and the bad guys change their code to make it undetectable again.
Effective deployments to prevent Malicious Code Typical preventive measures to protect against malicious code use technology, policies procedures, and training, all applied in a layered manner from perimeters inward to hosts data and servers. The controls are of the preventative and detective/corrective variety. Controls are applied at the host, network, and user levels: The protection suite can be elaborated under the following heads: A. Anti-Malware (Includes Anti-Virus and Anti-Spyware) B. URL Blocking and Content Scanning C. Host-Based Intrusion Prevention D. Patch Management E. Network Access Control / End-Point-Compliance A. Anti-Malware (Includes Anti-Virus and Anti-Spyware) Anti-Malware can be implemented by ensuring that the four aspects that govern it are addressed. Whether they are part of an integrated solution or a stand-alone, they must all be properly implemented to be effective. The four aspects of Anti-Malware are Anti-Virus, Anti-Spyware, Anti-Spam and a HIPS (Host based Intrusion Prevention System) component that includes a Personal Firewall. The following needs to be done for effective control and administration: Policies — Force anti-malware solutions to be resident and active on all computers — Lock down anti-malware policies so users can't disable them or stop scans and updates, implying that a user does not have administrator privileges. — Verify that all computers receive all product updates and signatures — Push signature updates out to all clients and servers daily — Block all non-essential ports from both incoming and outgoing connections at the clients/server Scans — Set up regular, daily and weekly scans for anti-virus and anti-spyware applications B. URL Blocking and Content scanning Previously the two areas of URL blocking and content scanning were managed separately, however now they have merged in recent years and as a result most solution providers now do both. Content scanning involves a gateway solution that inspects all incoming attachments and blocks malicious or unwanted contents based on the type of file, size, and kind of attachment or even by key words. URL blocking will deny access by either the contents of the site or through a scanning of possible dangerous conditions unknown to the end user. Many URL blocking systems today can also deny access to websites that are known to infect visitors. C. Host-Based Intrusion Prevention (HIPS) HIPS work at the host, or individual computer level. They look at incoming network traffic as well as local logon to the machine to determine if the connections should be allowed. Because HIPS systems can be implemented locally and can be managed as groups, they've become a much easier and faster solution to block both known as well as suspected malicious activity. D. Patch Management It is mandatory to keep a corporate computer updated with the latest operating system security updates, application patches and browser patches. It is a difficult proposition for most organisations, considering that most don't have the luxury of a homogeneous IT environment of just one type of computer with just one OS level. Most deal with literally hundreds of combinations of computer hardware, OS, applications and versions, as well as configurations. E. Network Access Control/End-point-Compliance Network Access Control (NAC), also called Network Admission Control, is a fairly recent development in the protection of IT through the regulation of connections from end user systems. NAC or end point compliance is a method of increasing network security for a closed IT environment by requiring authentication, authorization and security compliance before allowing a connection on the corporate network. NAC can also control or restrict what a user can do once they are on the network. The typical NAC scenario is to check the authentication of a user, verify the system is up-to date with all operating systems, browser and application patches, as well as anti-virus and anti-spyware updates, before allowing a controlled connection on the IT network. It can be configured to ensure access controls for roaming users also and works very effectively for rogue mobile devices including laptops, if connected to an organisation's network. Best defense against all attacks While technology plays a key role in organisational protection from malware, it needs to be part of a more comprehensive approach that involves user education and policies. Time invested in educating the user results in huge dividends. Unfortunately, updating a system is less time consuming than updating a human, but the latter is more promising as an option. The major vulnerability and hole in the best laid defense is a weak user base. Education and training plan for all levels of the organisation including administrators, end-users, and developers on their role and responsibility for information security within the organisation is one of the foremost strategies to prevent malware attacks. Effective response to a policy violation and ensuring policy enforcement is the best business continuity plan for any organisation. While anti-malware protection is still a major component of an in-depth defense strategy, IT professionals must continue to address malicious code on all fronts. Resilient software, continuous updates, policies enforcement, and especially education are all key to a successful anti-malware strategy. We need to understand that evolution of Malware has created a dynamic and unique security challenge for System and Network Administrators. In order to ensure healthy information traffic, the administrator needs to display an ability to integrate a heuristic and proactive approach, which results in greater reliability, increased protection and system high availability.